TOLOGIX - ISLG Maintenance

Project dealing with all ongoing maintenance of the current ISLG application (www.investorstatelawguide.com and dev.investorstatelawguide.com).

May 2019 scan - results

Assigned to
Harsh Parikh, Tech Lead at DevIT Harsh P. Jitesh Dhuravala, DevIT Jitesh D. Morgan Maguire, CEO Morgan M.
Notes

Comments & Events

Ryan Knuth, Customer Support Manager at Industrial
Hi all,

Please find attached the most recent scan. I suggest we delete or mark complete previous to-dos within this list as this scan will now supersede those issues.

Jitesh Dhuravala, DevIT Jitesh Please review the results, and let us know if you have any questions. I've attached the report in HTML as well. 

Once you're comfortable with the results I can create separate to-dos for each vulnerability.

Thanks!

Ryan
Morgan Maguire, CEO
Thanks Ryan Knuth, Customer Support Manager at Industrial Ryan .

I've completed all the old to-do. Jitesh Dhuravala, DevIT Jitesh , let us know which issues raised in the scan are critical (i.e., should be addressed immediately in the current), and which issues can be left to be dealt with in the new application.
 
Thanks,

Morgan 
Jitesh Dhuravala, DevIT
Hi Morgan Maguire, CEO Morgan ,

I have check ZAP Scanning Report and study each section. Please find attachment sheet of describe planning and resolution of both current and new ISLG of these security scan result.



Thanks,
Jitesh
 
Morgan Maguire, CEO
Hi Jitesh Dhuravala, DevIT Jitesh ,

Thanks for the report above. Just to clarify a few items, the report below states "Max Overcome" and "Overcome" in the ISLG Rebuild column. Could you clarify what is meant by these two terms? Does "Overcome" mean the issue is already resolved in the new application, and "Max Overcome" mean the team is working on resolving the issue? Please clarify.
Also, for the SQL injection problems, you remark, "Current ISLG major impact of functionality". Does this mean resolving these problems is going to take a significant amount of work to resolve? Also, will resolving these issues have impacts on the performance/functionality of the application?

Thanks,

Morgan
Ryan Knuth, Customer Support Manager at Industrial
Hi Jitesh Dhuravala, DevIT Jitesh

Thanks very much for going through the document. I have the same questions as Morgan Maguire, CEO Morgan .

Thanks!

Ryan
Jitesh Dhuravala, DevIT
Hi Morgan Maguire, CEO Morgan ,

Overcome means "
succeed in controlling"
Max Overcome means "Max try to controlling"

"Overcome" means it will be resolve in ISLGRebuild and "Max Overcome" means it will max points will be resolve in ISLGRebuild, In new ISLG we are focusing those security issues and max try to overcome.

Does "Overcome" mean the issue is already resolved in the new application, and "Max Overcome" mean the team is working on resolving the issue?


Yes, Morgan we are working in such manor to not facing these security attack in new ISLG.

Does this mean resolving these problems is going to take a significant amount of work to resolve? Also, will resolving these issues have impacts on the performance/functionality of the application?


Morgan, in current ISLG there are need lots of improvement and changes of work flow so it seems like redesign and development to overcome those sql injection in current ISLG. my suggesion is not do changes in current ISLG to resolving those points it will impact major functionality as well.

we will resolve and planning in new ISLG to not reproduce SQL Injection attack.

Let me know your feedback.

Thanks,
Jitesh
Morgan Maguire, CEO
Hi Jitesh Dhuravala, DevIT Jitesh ​,

Thank you for the clarification. Ok. I suppose if fixing the issues in the current application will require a significant amount of work, and may have affects on functionality, we'll hold off. However, please ensure all these issues are resolved in the new application.

We'll keep this report handy for reference purposes, and perform another scan as appropriate before launch.

Thanks,

Morgan
Morgan Maguire, CEO
Hi Ryan Knuth, Customer Support Manager at Industrial Ryan ,

A reminder to run the security scan on the non-member pages of ISLG.

Thanks,

Morgan 
Morgan Maguire, CEO
See above Jitesh Dhuravala, DevIT Jitesh .

Morgan
Jitesh Dhuravala, DevIT
I will look into it and let update you by tommorrow.

Thanks,
Jitesh
Morgan Maguire, CEO
Great. Thanks Jitesh Dhuravala, DevIT Jitesh .

Morgan 
Jitesh Dhuravala, DevIT
Hi Morgan Maguire, CEO Morgan ,

I have study security scan report on the non-member pages of ISLG and we are working on it. first we are taking Medium and low category and it will be done in 2-3 days.

High category will take it after complete medium and low Risk Level.

Thanks,
Jitesh
Morgan Maguire, CEO
Ok. Great, Jitesh Dhuravala, DevIT Jitesh .

Let us know as each issue is resolved.

Morgan 
Morgan Maguire, CEO
Hi Jitesh Dhuravala, DevIT Jitesh ,

Could you please provide an update on getting the issues in this to-do resolved? Please provide an itemized update on the high and medium risks alerts in the following report:





Thanks,

Morgan 
Jitesh Dhuravala, DevIT
Hi Morgan Maguire, CEO Morgan ,

We have resolved risk level Low category and looking into medium, High risk level impact major changes of development due to parameter passed in URL and some implementation of development structure so we will reduce High category in new approach in ISLG Rebuid.

Thanks,
Jitesh
Morgan Maguire, CEO
Hi Jitesh Dhuravala, DevIT Jitesh ,

As we've discussed above, we can leave the security issues concerning the members pages unresolved until the rebuild is complete, but all the issues for the public non-member pages, which are contained in the report above need to be resolved immediately. We can't continue to operate public web pages that could be vulnerable to a high risk attack. How do you suggest we address the issue?

Note that the public non-member pages were only setup last year, so I would assume that we could deal with these more easily than the member pages. If not, we may need to consider migrating all the public pages to a more secure CMS environment.

Morgan 
Morgan Maguire, CEO
Hello Jitesh Dhuravala, DevIT Jitesh , Harsh Parikh, Tech Lead at DevIT Harsh and Ryan Knuth, Customer Support Manager at Industrial Ryan ,
 
To sum up what we discussed earlier today, here is the plan for next steps on this issue:
  • Jitesh Dhuravala, DevIT Jitesh will prepare report summarizing how each issue raised in the most recent security can is being addressed.
  • Depending on what potential issues are outstanding, we will either run an additional scan on the non-member pages of www.islg; or we will get a security certificate issued on dev.islg, and run an additional scan on dev.islg.
Thanks,

Morgan 
Jitesh Dhuravala, DevIT
Hi Morgan Maguire, CEO Morgan ,

Following report showing how we will addressed issue raised in the recent security scanning report.


Yes Morgan, You can either run scan on www.islg or set security certificate on dev.islg. it will be useful to avoid reason which we know of site vulnerability.

Thanks,
Jitesh
Ryan Knuth, Customer Support Manager at Industrial
Great, thanks Jitesh Dhuravala, DevIT Jitesh .

I'll reach out to Carbon60 to see if they support Let's Encrypt certificates that we can get installed on dev.islg.

Ryan
Morgan Maguire, CEO
Great. Thanks Jitesh Dhuravala, DevIT Jitesh and Ryan Knuth, Customer Support Manager at Industrial Ryan . Looks like we'll get everything resolved to a satisfied state once we get the certificates installed on dev.islg.

Ryan Knuth, Customer Support Manager at Industrial Ryan , let me know if you need anything on my end to those ordered from Carbon60.
 
Thanks,

Morgan 
Morgan Maguire, CEO
Hi Ryan Knuth, Customer Support Manager at Industrial Ryan ,

Have we got a response from Carbon60 on getting the security certificates for dev.islg?

Thanks,

Morgan 
Ryan Knuth, Customer Support Manager at Industrial
Hi Morgan Maguire, CEO Morgan

Oddly nothing yet. I've followed up again.

Ryan
Morgan Maguire, CEO
Ok. Thanks Ryan Knuth, Customer Support Manager at Industrial Ryan

Please cc me on the email when you send it to Carbon60, so that I can follow-up if necessary.

Morgan 
Ryan Knuth, Customer Support Manager at Industrial
Hi Morgan Maguire, CEO Morgan  

They've responded with the following:

After reviewing internally, we can confirm that Let’s Encrypt is supported on this server, and if you would like your developers to install and manage the Let’s Encrypt application you may proceed at any time.
If however you would like any assistance from Carbon60 to install, we can absolutely assist and would engage our Professional Services team to help, which would require a quote and signoff from you before we proceed. If this is the path you’d like to take please let us know and we can initiate this process.

Harsh Parikh, Tech Lead at DevIT Harsh Jitesh Dhuravala, DevIT Jitesh do you have experience installing Let's Encrypt certificates?

Thanks!

Ryan
Jitesh Dhuravala, DevIT
Hi Ryan Knuth, Customer Support Manager at Industrial Ryan ,

I have study about Let' Encrypt Installation guideline on website. its seems like there is many dependency needed of network team when we start installation on server.  also we have not done same excise previously so it is better to do by them. it might be wrong effect on www.islg live site as both website configured on same server.
 

Thanks,
Jitesh
Ryan Knuth, Customer Support Manager at Industrial
Ok, thanks Jitesh Dhuravala, DevIT Jitesh .

Morgan Maguire, CEO Morgan I'll let you get in touch with Bik to see what the costs would be. It's worth assessing the cost of Carbon60 installing the free Lets Encrypt certificate vs. purchasing a certificate directly from them. It's hard for me to judge whether there would be any cost savings at that point.

Ryan
Morgan Maguire, CEO
Ok. Sounds good Ryan Knuth, Customer Support Manager at Industrial Ryan ​. However, did we implement this in www.islg? I'd like to confirm that first before I contact Bik.

Morgan
Ryan Knuth, Customer Support Manager at Industrial
No, we had purchased a certificate for www.islg that Carbon60 installed. 
Morgan Maguire, CEO
Ok. Sounds good. Could you forward me the email correspondence you've had so far with Carbon60 on this issue, and I'll see if Bik can assist in getting this implemented.

Thanks,

Morgan
Morgan Maguire, CEO
Ryan Knuth, Customer Support Manager at Industrial Ryan , just following up on this again. Could you please forward me the email correspondence so far with Carbon60 on this issue. I haven't been cc'd so far, I want to ensure I'm in the loop on what has been discussed so far before I contact Bik.

Thanks,

Morgan 
Ryan Knuth, Customer Support Manager at Industrial
Hi Morgan Maguire, CEO Morgan  

Sorry about that - I had meant to send it yesterday. I've just forwarded you the email thread.

Thanks!

Ryan
Morgan Maguire, CEO
Great. Thanks Ryan Knuth, Customer Support Manager at Industrial Ryan . I've sent the request off to Carbon60.

Morgan 
Morgan Maguire, CEO
Hi Harsh Parikh, Tech Lead at DevIT Harsh ,

Could you please reactivate the automated emails for dev.islg (I believe they are still disabled to run scans above). We need to create accounts on the development environment, and we can't do so until these automated emails are restored.

Thanks,

Morgan 
Harsh Parikh, Tech Lead at DevIT
Hi Morgan Maguire, CEO Morgan ,

We have reactivated the automated emails on dev.islg.
Morgan Maguire, CEO
Great. Thanks Harsh Parikh, Tech Lead at DevIT Harsh . Note that Carbon60 is installing the security certificate on dev.islg. I'll let you know when the work is complete, and then we'll run the final security test.

Morgan 
Ryan Knuth, Customer Support Manager at Industrial
Hi Harsh Parikh, Tech Lead at DevIT Harsh ,

Could you please suppress the emails again on dev.islg? Now that the cert is installed on dev.islg I will start the security scan of the non-member pages on Monday morning.

Thanks!

Ryan
Harsh Parikh, Tech Lead at DevIT
Hi Ryan Knuth, Customer Support Manager at Industrial Ryan ,

We have suppressed the emails on dev.islg.
Ryan Knuth, Customer Support Manager at Industrial
Thanks Harsh Parikh, Tech Lead at DevIT Harsh  !

Ryan
Ryan Knuth, Customer Support Manager at Industrial
Ryan Knuth completed this to-do.